diff --git a/advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json b/advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json index 31989c83aa9..a40c2cb0907 100644 --- a/advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json +++ b/advisories/unreviewed/2024/02/GHSA-394m-vxwj-363j/GHSA-394m-vxwj-363j.json @@ -1,13 +1,18 @@ { "schema_version": "1.4.0", "id": "GHSA-394m-vxwj-363j", - "modified": "2024-02-16T09:30:25Z", + "modified": "2025-01-06T12:30:31Z", "published": "2024-02-16T09:30:25Z", "aliases": [ "CVE-2023-49508" ], "details": "Directory Traversal vulnerability in YetiForceCompany YetiForceCRM versions 6.4.0 and before allows a remote authenticated attacker to obtain sensitive information via the license parameter in the LibraryLicense.php component.", - "severity": [], + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" + } + ], "affected": [], "references": [ { @@ -28,8 +33,10 @@ } ], "database_specific": { - "cwe_ids": [], - "severity": null, + "cwe_ids": [ + "CWE-22" + ], + "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2024-02-16T08:15:39Z" diff --git a/advisories/unreviewed/2025/01/GHSA-38h4-hmr8-8c7q/GHSA-38h4-hmr8-8c7q.json b/advisories/unreviewed/2025/01/GHSA-38h4-hmr8-8c7q/GHSA-38h4-hmr8-8c7q.json new file mode 100644 index 00000000000..995c7773794 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-38h4-hmr8-8c7q/GHSA-38h4-hmr8-8c7q.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-38h4-hmr8-8c7q", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45541" + ], + "details": "Memory corruption when IOCTL call is invoked from user-space to read board data.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45541" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4fvr-c9qm-r85w/GHSA-4fvr-c9qm-r85w.json b/advisories/unreviewed/2025/01/GHSA-4fvr-c9qm-r85w/GHSA-4fvr-c9qm-r85w.json new file mode 100644 index 00000000000..c5290a67095 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4fvr-c9qm-r85w/GHSA-4fvr-c9qm-r85w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4fvr-c9qm-r85w", + "modified": "2025-01-06T12:30:32Z", + "published": "2025-01-06T12:30:32Z", + "aliases": [ + "CVE-2024-33055" + ], + "details": "Memory corruption while invoking IOCTL calls to unmap the DMA buffers.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33055" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-4q6j-vwqc-gp8r/GHSA-4q6j-vwqc-gp8r.json b/advisories/unreviewed/2025/01/GHSA-4q6j-vwqc-gp8r/GHSA-4q6j-vwqc-gp8r.json new file mode 100644 index 00000000000..1de947be74f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-4q6j-vwqc-gp8r/GHSA-4q6j-vwqc-gp8r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-4q6j-vwqc-gp8r", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45542" + ], + "details": "Memory corruption when IOCTL call is invoked from user-space to write board data to WLAN driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45542" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-121" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-7q27-3v2r-ccj9/GHSA-7q27-3v2r-ccj9.json b/advisories/unreviewed/2025/01/GHSA-7q27-3v2r-ccj9/GHSA-7q27-3v2r-ccj9.json new file mode 100644 index 00000000000..ee475b57279 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-7q27-3v2r-ccj9/GHSA-7q27-3v2r-ccj9.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-7q27-3v2r-ccj9", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-33067" + ], + "details": "Information disclosure while invoking callback function of sound model driver from ADSP for every valid opcode received from sound model driver.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33067" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-cf88-f3cc-2r22/GHSA-cf88-f3cc-2r22.json b/advisories/unreviewed/2025/01/GHSA-cf88-f3cc-2r22/GHSA-cf88-f3cc-2r22.json new file mode 100644 index 00000000000..0741f5159d0 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-cf88-f3cc-2r22/GHSA-cf88-f3cc-2r22.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-cf88-f3cc-2r22", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45559" + ], + "details": "Transient DOS can occur when GVM sends a specific message type to the Vdev-FastRPC backend.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45559" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-g9w9-pqmh-3hm7/GHSA-g9w9-pqmh-3hm7.json b/advisories/unreviewed/2025/01/GHSA-g9w9-pqmh-3hm7/GHSA-g9w9-pqmh-3hm7.json new file mode 100644 index 00000000000..6bc1a3e8c69 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-g9w9-pqmh-3hm7/GHSA-g9w9-pqmh-3hm7.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-g9w9-pqmh-3hm7", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45553" + ], + "details": "Memory corruption can occur when process-specific maps are added to the global list. If a map is removed from the global list while another thread is using it for a process-specific task, issues may arise.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45553" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-h6qx-c9g7-659w/GHSA-h6qx-c9g7-659w.json b/advisories/unreviewed/2025/01/GHSA-h6qx-c9g7-659w/GHSA-h6qx-c9g7-659w.json new file mode 100644 index 00000000000..7d0fdf7dcbd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-h6qx-c9g7-659w/GHSA-h6qx-c9g7-659w.json @@ -0,0 +1,34 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-h6qx-c9g7-659w", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-43064" + ], + "details": "Uncontrolled resource consumption when a driver, an application or a SMMU client tries to access the global registers through SMMU.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43064" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hmch-8qfm-f6mp/GHSA-hmch-8qfm-f6mp.json b/advisories/unreviewed/2025/01/GHSA-hmch-8qfm-f6mp/GHSA-hmch-8qfm-f6mp.json new file mode 100644 index 00000000000..8eb9fb4c477 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hmch-8qfm-f6mp/GHSA-hmch-8qfm-f6mp.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hmch-8qfm-f6mp", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-12970" + ], + "details": "Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in TUBITAK BILGEM Pardus OS My Computer allows OS Command Injection.This issue affects Pardus OS My Computer: before 0.7.2.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:P/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-12970" + }, + { + "type": "WEB", + "url": "https://www.usom.gov.tr/bildirim/tr-24-1900" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-78" + ], + "severity": "LOW", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T12:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hvg8-7678-v53j/GHSA-hvg8-7678-v53j.json b/advisories/unreviewed/2025/01/GHSA-hvg8-7678-v53j/GHSA-hvg8-7678-v53j.json new file mode 100644 index 00000000000..f6194e58c98 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hvg8-7678-v53j/GHSA-hvg8-7678-v53j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hvg8-7678-v53j", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45548" + ], + "details": "Memory corruption while processing FIPS encryption or decryption validation functionality IOCTL call.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45548" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-hwhf-72f8-crgh/GHSA-hwhf-72f8-crgh.json b/advisories/unreviewed/2025/01/GHSA-hwhf-72f8-crgh/GHSA-hwhf-72f8-crgh.json new file mode 100644 index 00000000000..268a81a7a56 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-hwhf-72f8-crgh/GHSA-hwhf-72f8-crgh.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-hwhf-72f8-crgh", + "modified": "2025-01-06T12:30:32Z", + "published": "2025-01-06T12:30:32Z", + "aliases": [ + "CVE-2024-23366" + ], + "details": "Information Disclosure while invoking the mailbox write API when message received from user is larger than mailbox size.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-23366" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:07Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-jj76-44fx-5g9w/GHSA-jj76-44fx-5g9w.json b/advisories/unreviewed/2025/01/GHSA-jj76-44fx-5g9w/GHSA-jj76-44fx-5g9w.json new file mode 100644 index 00000000000..b1d691a41fd --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-jj76-44fx-5g9w/GHSA-jj76-44fx-5g9w.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-jj76-44fx-5g9w", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45558" + ], + "details": "Transient DOS can occur when the driver parses the per STA profile IE and tries to access the EXTN element ID without checking the IE length.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45558" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-mqh3-w8fw-j85c/GHSA-mqh3-w8fw-j85c.json b/advisories/unreviewed/2025/01/GHSA-mqh3-w8fw-j85c/GHSA-mqh3-w8fw-j85c.json new file mode 100644 index 00000000000..49df00ccc22 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-mqh3-w8fw-j85c/GHSA-mqh3-w8fw-j85c.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-mqh3-w8fw-j85c", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45550" + ], + "details": "Memory corruption occurs when invoking any IOCTL-calling application that executes all MCDM driver IOCTL calls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45550" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-129" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p6wf-f62f-3j43/GHSA-p6wf-f62f-3j43.json b/advisories/unreviewed/2025/01/GHSA-p6wf-f62f-3j43/GHSA-p6wf-f62f-3j43.json new file mode 100644 index 00000000000..e0921091b56 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p6wf-f62f-3j43/GHSA-p6wf-f62f-3j43.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p6wf-f62f-3j43", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45547" + ], + "details": "Memory corruption while processing IOCTL call invoked from user-space to verify non extension FIPS encryption and decryption functionality.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45547" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p762-67q5-3hrq/GHSA-p762-67q5-3hrq.json b/advisories/unreviewed/2025/01/GHSA-p762-67q5-3hrq/GHSA-p762-67q5-3hrq.json new file mode 100644 index 00000000000..b848d5bcc98 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p762-67q5-3hrq/GHSA-p762-67q5-3hrq.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p762-67q5-3hrq", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45546" + ], + "details": "Memory corruption while processing FIPS encryption or decryption IOCTL call invoked from user-space.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45546" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:09Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-p93q-wj5g-6w29/GHSA-p93q-wj5g-6w29.json b/advisories/unreviewed/2025/01/GHSA-p93q-wj5g-6w29/GHSA-p93q-wj5g-6w29.json new file mode 100644 index 00000000000..b21fa4c94a5 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-p93q-wj5g-6w29/GHSA-p93q-wj5g-6w29.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-p93q-wj5g-6w29", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-33059" + ], + "details": "Memory corruption while processing frame command IOCTL calls.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33059" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-416" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-r4m8-fhqx-9796/GHSA-r4m8-fhqx-9796.json b/advisories/unreviewed/2025/01/GHSA-r4m8-fhqx-9796/GHSA-r4m8-fhqx-9796.json new file mode 100644 index 00000000000..34a576ccbcc --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-r4m8-fhqx-9796/GHSA-r4m8-fhqx-9796.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-r4m8-fhqx-9796", + "modified": "2025-01-06T12:30:32Z", + "published": "2025-01-06T12:30:32Z", + "aliases": [ + "CVE-2024-21464" + ], + "details": "Memory corruption while processing IPA statistics, when there are no active clients registered.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-21464" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-120" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:06Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-rjpg-qpwf-xp3r/GHSA-rjpg-qpwf-xp3r.json b/advisories/unreviewed/2025/01/GHSA-rjpg-qpwf-xp3r/GHSA-rjpg-qpwf-xp3r.json new file mode 100644 index 00000000000..9ba3c0475f3 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-rjpg-qpwf-xp3r/GHSA-rjpg-qpwf-xp3r.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-rjpg-qpwf-xp3r", + "modified": "2025-01-06T12:30:32Z", + "published": "2025-01-06T12:30:32Z", + "aliases": [ + "CVE-2024-33041" + ], + "details": "Memory corruption when input parameter validation for number of fences is missing for fence frame IOCTL calls,", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33041" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-823" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-vpg3-wxv6-fm2j/GHSA-vpg3-wxv6-fm2j.json b/advisories/unreviewed/2025/01/GHSA-vpg3-wxv6-fm2j/GHSA-vpg3-wxv6-fm2j.json new file mode 100644 index 00000000000..d569336d68f --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-vpg3-wxv6-fm2j/GHSA-vpg3-wxv6-fm2j.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-vpg3-wxv6-fm2j", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-43063" + ], + "details": "information disclosure while invoking the mailbox read API.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-43063" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:08Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-wmhm-48vh-qjwg/GHSA-wmhm-48vh-qjwg.json b/advisories/unreviewed/2025/01/GHSA-wmhm-48vh-qjwg/GHSA-wmhm-48vh-qjwg.json new file mode 100644 index 00000000000..a494323b879 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-wmhm-48vh-qjwg/GHSA-wmhm-48vh-qjwg.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-wmhm-48vh-qjwg", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-45555" + ], + "details": "Memory corruption can occur if an already verified IFS2 image is overwritten, bypassing boot verification. This allows unauthorized programs to be injected into security-sensitive images, enabling the booting of a tampered IFS2 system image.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45555" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-787" + ], + "severity": "HIGH", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:10Z" + } +} \ No newline at end of file diff --git a/advisories/unreviewed/2025/01/GHSA-x7f5-x9wp-mgqw/GHSA-x7f5-x9wp-mgqw.json b/advisories/unreviewed/2025/01/GHSA-x7f5-x9wp-mgqw/GHSA-x7f5-x9wp-mgqw.json new file mode 100644 index 00000000000..f6a19a9a2b6 --- /dev/null +++ b/advisories/unreviewed/2025/01/GHSA-x7f5-x9wp-mgqw/GHSA-x7f5-x9wp-mgqw.json @@ -0,0 +1,36 @@ +{ + "schema_version": "1.4.0", + "id": "GHSA-x7f5-x9wp-mgqw", + "modified": "2025-01-06T12:30:33Z", + "published": "2025-01-06T12:30:33Z", + "aliases": [ + "CVE-2024-33061" + ], + "details": "Information disclosure while processing IOCTL call made for releasing a trusted VM process release or opening a channel without initializing the process.", + "severity": [ + { + "type": "CVSS_V3", + "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:L" + } + ], + "affected": [], + "references": [ + { + "type": "ADVISORY", + "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-33061" + }, + { + "type": "WEB", + "url": "https://docs.qualcomm.com/product/publicresources/securitybulletin/january-2025-bulletin.html" + } + ], + "database_specific": { + "cwe_ids": [ + "CWE-126" + ], + "severity": "MODERATE", + "github_reviewed": false, + "github_reviewed_at": null, + "nvd_published_at": "2025-01-06T11:15:08Z" + } +} \ No newline at end of file